It's not just OpenAI models that have gone rogue. Claude Cowork could read files on Mac it shouldn't have had access to

  • Security experts showed that the AI tool Claude Cowork was able to escape its isolated environment on Mac
  • The agent thus gained access to private files across the entire user account, including access keys and cloud passwords
  • This follows a recent case where two OpenAI models escaped from the lab

Sdílejte:
Adam Kurfürst
Adam Kurfürst
28. 7. 2026 10:30
Claude Fable 5 a model Mythos od společnosti Anthropic
Advertisement

A few days ago, we wrote about how OpenAI lost control of its models during a test and they breached a third-party company. Now it turns out that a similar vulnerability doesn’t only plague the competition: security firm Accomplish demonstrated that even Anthropic’s Claude Cowork was able to bypass its own sandbox and access files it should have been completely out of reach of.

Smart assistant escaped from isolated environment

Claude Cowork is an AI assistant from Anthropic that performs tasks for you on your computer – it goes through a folder, modifies files, finds something. To prevent it from causing damage, it runs enclosed in its own isolated environment (technically a sandbox, a kind of “sandpit”) and should only see the single folder you give it access to.

However, this boundary was successfully breached. Researchers from Accomplish started a fresh session, shared a single folder with the agent, and sent it one short message. “We watched the agent escape the sandbox,” described one of them, Oren Yomtov. Instead of staying within the defined space, it spread to files across the entire account.

Agent could access sensitive data

Once the agent was out of the sandbox, it could read and overwrite files anywhere in the account – even where a regular program is not allowed without permission. Among what it was able to read were login keys and access credentials for cloud services – precisely the sensitive information with which a potential attacker can cause the most damage.

According to the researchers, the problem affected approximately half a million people who ran Cowork directly on their Macs. It should be added that this was not a real external attack – it was a controlled demonstration by security experts who described and reported the vulnerability. However, the risk was entirely real.

How did Anthropic react?

According to the researchers, the company closed the report as “informative” without issuing a direct fix. However, newer versions of Cowork by default run in the cloud, not directly on your computer – thus bypassing the escape route from Mac. But anyone who knowingly enables it to run directly on the device remains exposed to risk, according to experts.

Both cases – the escaped OpenAI models and this Cowork vulnerability – follow the same pattern. We are giving artificial intelligence more and more autonomy and access to our data, but the walls meant to keep it in check are not yet as strong as they first appear.

Would you let an AI assistant access files directly on your computer?

Sources: Accomplish, The Hacker News, TechRadar

About the author

Adam Kurfürst

Adam studuje na gymnáziu a technologické žurnalistice se věnuje od svých 14 let. Pakliže pomineme jeho vášeň pro chytré telefony, tablety a příslušenství, rád se… More about the author

Adam Kurfürst
Sdílejte: